cbcvebase.

Debian Linux vulnerabilities

9,953 known vulnerabilities affecting debian/debian_linux.

Total CVEs
9,953
CISA KEV
121
actively exploited
Public exploits
460
Exploited in wild
210
Severity breakdown
CRITICAL1133HIGH4150MEDIUM4312LOW358

Vulnerabilities

Page 179 of 498
CVE-2022-1650P3CRITICALCVSS 9.3v10.02022-05-12
CVE-2022-1650 [CRITICAL] CWE-212 CVE-2022-1650: Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsourc Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
nvd
CVE-2018-12361P3HIGHCVSS 8.8v8.0v9.02018-10-18
CVE-2018-12361 [HIGH] CWE-190 CVE-2018-12361: An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2020-15810P3MEDIUMCVSS 6.5v9.0v10.02020-09-02
CVE-2020-15810 [MEDIUM] CWE-444 CVE-2020-15810: An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local security and poison the proxy cache and any downstream caches with content fr
nvd
CVE-2019-14904P3HIGHCVSS 7.3v9.0v10.02020-08-26
CVE-2019-14904 [HIGH] CWE-20 CVE-2019-14904: A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the nam A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw by crafting the name of the zone and executing arbitrary commands in the r
nvd
CVE-2017-7645P3HIGHCVSS 7.5v8.0v9.02017-04-18
CVE-2017-7645 [HIGH] CWE-20 CVE-2017-7645: The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attac The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, and fs/nfsd/nfsxdr.c.
nvd
CVE-2015-1774P3MEDIUMCVSS 6.8v7.0v8.02015-04-28
CVE-2015-1774 [MEDIUM] CWE-787 CVE-2015-1774: The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
nvd
CVE-2021-25217P3HIGHCVSS 7.4v9.02021-05-26
CVE-2021-25217 [HIGH] CWE-119 CVE-2021-25217: In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., re In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the defect is also present in releases from those series, but they have not been of
nvd
CVE-2021-20254P3MEDIUMCVSS 6.8v9.02021-05-05
CVE-2021-20254 [MEDIUM] CWE-125 CVE-2021-20254: A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the array in the case where a negative cache entry had been added to the mapping cache. This could cause the calling code to return those v
nvd
CVE-2017-17501P3HIGHCVSS 8.8v7.0v8.0+1 more2017-12-11
CVE-2017-17501 [HIGH] CWE-125 CVE-2017-17501: WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a cr WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.
nvd
CVE-2015-5219P3HIGHCVSS 7.5v7.0v8.02017-07-21
CVE-2015-5219 [HIGH] CWE-704 CVE-2015-5219: The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions fr The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
nvd
CVE-2014-9274P3HIGHCVSS 7.5v7.0v8.02014-12-09
CVE-2014-9274 [HIGH] CWE-119 CVE-2014-9274: UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary co UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".
nvd
CVE-2017-14169P3HIGHCVSS 8.8v8.0v9.02017-09-07
CVE-2017-14169 [HIGH] CWE-20 CVE-2017-14169: In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer sign In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_num" turns negative, bypassing the check for a large value.
nvd
CVE-2012-1970P3CRITICALCVSS 10.0v6.0v7.02012-08-29
CVE-2012-1970 [CRITICAL] CWE-119 CVE-2012-1970: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown
nvd
CVE-2019-17024P3HIGHCVSS 8.8v8.0v9.0+1 more2020-01-08
CVE-2019-17024 [HIGH] CWE-787 CVE-2019-17024: Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of t Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2017-5436P3HIGHCVSS 8.8v8.02018-06-11
CVE-2017-5436 [HIGH] CWE-787 CVE-2017-5436: An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2016-9905P3HIGHCVSS 8.8v8.02018-06-11
CVE-2016-9905 [HIGH] CWE-284 CVE-2016-9905: A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. T A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
nvd
CVE-2018-5130P3HIGHCVSS 8.8v7.0v8.0+1 more2018-06-11
CVE-2018-5130 [HIGH] CWE-20 CVE-2018-5130: When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstance When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
nvd
CVE-2018-12389P3HIGHCVSS 8.8v8.0v9.02019-02-28
CVE-2018-12389 [HIGH] CWE-119 CVE-2018-12389: Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. So Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.
nvd
CVE-2019-10899P3HIGHCVSS 7.5v8.0v9.02019-04-09
CVE-2019-10899 [HIGH] CWE-125 CVE-2019-10899: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.
nvd
CVE-2005-2557P4MEDIUMCVSS 4.3PoCv3.12005-09-28
CVE-2005-2557 [MEDIUM] CVE-2005-2557: Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allo Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.
nvd
Debian Linux vulnerabilities | cvebase